A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.
https://www.theregister.com/2024/11/14/fortinet_vpn_authentication_bypass_bug/
https://pentera.io/resources/research/two-zero-days-forticlient-vpn-2024/